RFR: 8258833: Cancel multi-part cipher operations in SunPKCS11 after failures

Valerie Peng valeriep at openjdk.java.net
Wed Jan 13 00:55:55 UTC 2021


On Tue, 12 Jan 2021 21:38:32 GMT, Martin Balao <mbalao at openjdk.org> wrote:

> 
> 
> > For cipher impls, there are more than just P11Cipher, there are also P11AEADCipher and P11RSACipher. It looks like they should be updated with this defensive cancellation change unless the non-compliant NSS impl is algorithm-specific and does not apply to AES/GCM and RSA.
> 
> Sure, I was going to go through each of them. Only P11Cipher and P11Signature so far but I'm working on this.

Wonderful, thanks!

-------------

PR: https://git.openjdk.java.net/jdk/pull/1901


More information about the security-dev mailing list